Ransomware OldGremlin

The OldGremlin ransomware started its activities around March 2020. Although apparently Russian-speaking, OldGremlin ransomware primarily targets Russian institutions such as national banks, private companies in the industrial or medical fields.

According to Oleg Skulkin, a forensic analyst at Group-IB, the perpetrators of these attacks are the only Russian-speaking ransomware operators to violate the dictated rule about not working in Russia and post-Soviet countries.

Through Ransomware as a Service (RaaS), OldGremlin has achieved a significant increase in the numbers of its attacks. The value of the group’s ransomware kit is relatively low, thus making it easy for anyone to immerse themselves in the murky world of ransomware attacks and, consequently, increasing the group’s power and relevance on the world stage.

Upon accessing the environment, thanks to human interactions in malicious emails, the OldGremlin ransomware downloads and executes additional malware that frees remote access to the attack operators. In most cases all this happens without the victim noticing any unusual activity.

In all their attacks, the group behind OldGremlin has displayed boundless imagination. Besides relying on their custom tools TinyPosh and TinyNode to access the victim’s environment, spear-phishing emails with very different motives are also used.

It is reported that in their emails, the OldGremlin group has posed as a COVID-19 prevention organization, financial institutions, Russian dental clinics, and even a Russian journalist for RBC.

With the methods of cybercriminals becoming more and more inventive, the question about ransomware attacks is no longer ‘will we be attacked’, but ‘when will we be attacked’. For this reason, being in good company when the tragic day arrives is essential.

Recover files encrypted by OldGremlin ransomware

Digital Recovery has been helping companies recover their data for over 23 years. Over the years, we have acquired important know-how that has made us one of the leading companies in recovery of data encrypted by ransomware.

Our development team has managed to come up with a solution that enables data recovery on almost any storage device, such as servers, databases, virtual machines, RAID systems, and others.

We understand the importance of each of our customers’ data. For this reason, we act discreetly and securely. We have a confidentiality agreement (NDA) on every project.

Our experts are available 24/7, and in most cases recovery can be done completely remotely.

So, contact us and make your diagnosis now.

We are always online

Please fill out the form, or select your preferred contact method. We will contact you to start recovering your files.

Latest insights from our experts

Melhores HDs

Best HD brands

When talking about the best hard disk drive (HDD) brands, it’s important to consider various aspects such as reliability, performance, storage capacity and value for


Through unique technologies Digital Recovery can bring back encrypted data on any storage device, offering remote solutions anywhere in the world.

Discover the invisible vulnerabilities in your IT – with the 4D Pentest from Digital Recovery